Amazon Cognito · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Amazon Cognito Identity Provider API

104 actions 104 updates phrasing extends openapi/amazon-cognito-amazon-cognito-identity-provider-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Amazon Cognito's API. It is a proposal applied on top of the contract, not a document Amazon Cognito publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 104 · first 16 shown; the file carries all of them

$.info
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AddCustomAttributes'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminAddUserToGroup'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminConfirmSignUp'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminCreateUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUserAttributes'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableProviderForUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminEnableUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminForgetDevice'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetDevice'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminInitiateAuth'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminLinkProviderForUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListDevices'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Amazon Cognito Identity Provider API
  version: 1.0.0
extends: openapi/amazon-cognito-amazon-cognito-identity-provider-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 103
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AddCustomAttributes'].post
  update:
    x-apievangelist-phrasing:
      intent: Add custom attributes to a user pool
      effect: write
      questions:
      - How do I add a custom profile field like a loyalty tier to my Cognito user pool?
      - Can new custom attributes be added to a user pool that already has users?
      instructions:
      - text: Add custom attributes {attributes} to user pool {user_pool_id}.
        slots:
          attributes: requestBody.CustomAttributes
          user_pool_id: requestBody.UserPoolId
      - text: Extend the schema of pool {user_pool_id} with new custom fields {attributes}.
        slots:
          user_pool_id: requestBody.UserPoolId
          attributes: requestBody.CustomAttributes
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminAddUserToGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a user to a group
      effect: write
      questions:
      - How do I put an existing user into an admins group in my user pool?
      - Can I grant a user a group's IAM role by adding them to that group?
      instructions:
      - text: Add user {username} to group {group} in user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
      - text: Make {username} a member of the {group} group in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminConfirmSignUp'].post
  update:
    x-apievangelist-phrasing:
      intent: Confirm a user's sign-up as an administrator
      effect: write
      questions:
      - Can an admin confirm a new user's registration without them entering a verification code?
      - How do I manually approve a user stuck in unconfirmed status?
      instructions:
      - text: Confirm the sign-up for user {username} in pool {user_pool_id} as an admin.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Mark unconfirmed user {username} in pool {user_pool_id} as confirmed without a code.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminCreateUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a new user as an administrator
      effect: write
      questions:
      - How do I create a user account on someone's behalf and send them an invitation?
      - Can I set a temporary password when an admin creates a user?
      - Is there a way to create a user without sending the welcome message?
      instructions:
      - text: Create user {username} in user pool {user_pool_id} with attributes {attributes}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          attributes: requestBody.UserAttributes
      - text: Invite new user {username} to pool {user_pool_id} with temporary password {temp_password}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          temp_password: requestBody.TemporaryPassword
      - text: Admin-create {username} in pool {user_pool_id} and deliver the invite by {mediums}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          mediums: requestBody.DesiredDeliveryMediums
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete a user as an administrator
      effect: destructive
      questions:
      - How can an admin permanently remove any user from a user pool?
      - Can I delete a user account by username from the backend?
      instructions:
      - text: Delete user {username} from user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, permanently remove {username}'s account from pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUserAttributes'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete attributes from a user as an administrator
      effect: destructive
      questions:
      - How does an admin clear a field like phone number from a specific user's profile?
      - Can I remove several attributes from one user at once from the backend?
      instructions:
      - text: Delete attributes {attribute_names} from user {username} in pool {user_pool_id}.
        slots:
          attribute_names: requestBody.UserAttributeNames
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, clear {attribute_names} off {username}'s profile in pool {user_pool_id}.
        slots:
          attribute_names: requestBody.UserAttributeNames
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableProviderForUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Unlink a federated user from a local user
      effect: destructive
      questions:
      - How do I stop a federated user from signing in through the Cognito account they were linked to?
      - Can I remove the link between a social login and a native user pool account?
      instructions:
      - text: Disable the external provider link for user {user} in pool {user_pool_id}.
        slots:
          user: requestBody.User
          user_pool_id: requestBody.UserPoolId
      - text: Unlink federated identity {user} from its linked account in user pool {user_pool_id}.
        slots:
          user: requestBody.User
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable a user account
      effect: destructive
      questions:
      - How do I block a user from signing in without deleting their account?
      - Can I suspend a user in a user pool and turn them back on later?
      instructions:
      - text: Disable user {username} in user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Suspend {username}'s sign-in access in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminEnableUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Re-enable a disabled user
      effect: write
      questions:
      - How do I restore sign-in for a user I previously disabled?
      - Can a suspended Cognito user be reactivated?
      instructions:
      - text: Enable user {username} in user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Reactivate the disabled account {username} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminForgetDevice'].post
  update:
    x-apievangelist-phrasing:
      intent: Forget a user's remembered device as an admin
      effect: destructive
      questions:
      - How can an admin remove a remembered device from a user's account?
      - Can I make a pool stop trusting one of a user's devices from the backend?
      instructions:
      - text: Forget device {device_key} for user {username} in pool {user_pool_id}.
        slots:
          device_key: requestBody.DeviceKey
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, drop remembered device {device_key} from {username}'s account in pool {user_pool_id}.
        slots:
          device_key: requestBody.DeviceKey
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetDevice'].post
  update:
    x-apievangelist-phrasing:
      intent: Get a user's device as an admin
      effect: read
      questions:
      - How does an admin look up details of one specific device a user has signed in from?
      - Can I see when a user's device was last authenticated from the backend?
      instructions:
      - text: Get device {device_key} for user {username} in pool {user_pool_id}.
        slots:
          device_key: requestBody.DeviceKey
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, show the details of {username}'s device {device_key} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          device_key: requestBody.DeviceKey
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Look up a user by username as an admin
      effect: read
      questions:
      - How do I fetch a user's attributes and account status by their username?
      - Can an admin check whether a specific user is confirmed or enabled?
      instructions:
      - text: Get user {username} from user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Show the status, MFA settings and attributes for {username} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminInitiateAuth'].post
  update:
    x-apievangelist-phrasing:
      intent: Start sign-in for a user from a backend server
      effect: write
      questions:
      - How does my server-side app start authenticating a user with admin credentials?
      - Which auth flows can a backend use to sign a user in with their username and password?
      instructions:
      - text: Start server-side authentication with flow {auth_flow} for app client {client_id} in pool {user_pool_id}.
        slots:
          auth_flow: requestBody.AuthFlow
          client_id: requestBody.ClientId
          user_pool_id: requestBody.UserPoolId
      - text: Sign a user in from my backend to pool {user_pool_id} via client {client_id} using flow {auth_flow} and parameters {auth_params}.
        slots:
          user_pool_id: requestBody.UserPoolId
          client_id: requestBody.ClientId
          auth_flow: requestBody.AuthFlow
          auth_params: requestBody.AuthParameters
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminLinkProviderForUser'].post
  update:
    x-apievangelist-phrasing:
      intent: Link a federated identity to an existing user
      effect: write
      questions:
      - How do I link a user's social login to their existing native Cognito account?
      - Can a federated user sign in as an existing local user after linking?
      instructions:
      - text: Link external identity {source_user} to existing user {destination_user} in pool {user_pool_id}.
        slots:
          source_user: requestBody.SourceUser
          destination_user: requestBody.DestinationUser
          user_pool_id: requestBody.UserPoolId
      - text: Connect federated login {source_user} with local account {destination_user} in user pool {user_pool_id}.
        slots:
          source_user: requestBody.SourceUser
          destination_user: requestBody.DestinationUser
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListDevices'].post
  update:
    x-apievangelist-phrasing:
      intent: List a user's devices as an admin
      effect: read
      questions:
      - How can an admin see every device a particular user has remembered?
      - Can I page through a user's devices from the backend?
      instructions:
      - text: List the devices for user {username} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, show up to {limit} of {username}'s remembered devices in pool {user_pool_id}.
        slots:
          limit: requestBody.Limit
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListGroupsForUser'].post
  update:
    x-apievangelist-phrasing:
      intent: List the groups a user belongs to
      effect: read
      questions:
      - Which groups is a given user a member of in my user pool?
      - How do I check a user's group memberships before changing their permissions?
      instructions:
      - text: List the groups user {username} belongs to in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Show {username}'s group memberships in user pool {user_pool_id}, {limit} per page.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          limit: requestBody.Limit
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListUserAuthEvents'].post
  update:
    x-apievangelist-phrasing:
      intent: View a user's sign-in history and risk events
      effect: read
      questions:
      - How can I see a user's recent sign-in attempts and their risk ratings?
      - Does Cognito keep an auth event history I can review for a suspicious account?
      instructions:
      - text: List the authentication events for user {username} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Show the last {max} sign-in events and risk results for {username} in pool {user_pool_id}.
        slots:
          max: requestBody.MaxResults
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminRemoveUserFromGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a user from a group
      effect: destructive
      questions:
      - How do I take a user out of a group in my user pool?
      - Can I revoke a user's group-based role by removing their membership?
      instructions:
      - text: Remove user {username} from group {group} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
      - text: Take {username} out of the {group} group in user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminResetUserPassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Force a password reset for a user
      effect: write
      questions:
      - How does an admin invalidate a user's password and make them reset it with a code?
      - Can I force a user to choose a new password at next sign-in?
      instructions:
      - text: Reset the password for user {username} in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Invalidate {username}'s current password in pool {user_pool_id} and send them a reset code.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminRespondToAuthChallenge'].post
  update:
    x-apievangelist-phrasing:
      intent: Answer a sign-in challenge from a backend server
      effect: write
      questions:
      - How does my server respond to an MFA or new-password challenge during admin sign-in?
      - What do I send back when server-side authentication returns a challenge?
      instructions:
      - text: Respond to challenge {challenge} for client {client_id} in pool {user_pool_id} with {responses}.
        slots:
          challenge: requestBody.ChallengeName
          client_id: requestBody.ClientId
          user_pool_id: requestBody.UserPoolId
          responses: requestBody.ChallengeResponses
      - text: From my backend, answer the {challenge} challenge in session {session} for app client {client_id} in pool {user_pool_id}.
        slots:
          challenge: requestBody.ChallengeName
          session: requestBody.Session
          client_id: requestBody.ClientId
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserMFAPreference'].post
  update:
    x-apievangelist-phrasing:
      intent: Set a user's MFA preference as an admin
      effect: write
      questions:
      - How can an admin turn on authenticator app MFA for a specific user?
      - Can I choose SMS as the preferred MFA method for someone else's account?
      instructions:
      - text: Set the MFA preference for user {username} in pool {user_pool_id} to SMS settings {sms}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          sms: requestBody.SMSMfaSettings
      - text: As an admin, enable authenticator app MFA for {username} in pool {user_pool_id} with settings {totp}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          totp: requestBody.SoftwareTokenMfaSettings
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserPassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Set a user's password as an admin
      effect: write
      questions:
      - How does an admin set a specific password for a user directly?
      - Can I make an admin-set password permanent so the user is not forced to change it?
      instructions:
      - text: Set the password for user {username} in pool {user_pool_id} to {password}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          password: requestBody.Password
      - text: 'Give {username} in pool {user_pool_id} the password {password}, permanent: {permanent}.'
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          password: requestBody.Password
          permanent: requestBody.Permanent
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserSettings'].post
  update:
    x-apievangelist-phrasing:
      intent: Set a user's legacy SMS MFA options as an admin
      effect: write
      questions:
      - Is there an older admin endpoint for setting a user's SMS MFA delivery options?
      - How do I configure the legacy MFAOptions for a specific user from the backend?
      instructions:
      - text: Set legacy MFA options {mfa_options} for user {username} in pool {user_pool_id}.
        slots:
          mfa_options: requestBody.MFAOptions
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: Using the older admin user settings call, apply MFAOptions {mfa_options} to {username} in pool {user_pool_id}.
        slots:
          mfa_options: requestBody.MFAOptions
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateAuthEventFeedback'].post
  update:
    x-apievangelist-phrasing:
      intent: Mark a user's sign-in event as valid or invalid
      effect: write
      questions:
      - How can an admin flag a risky sign-in event as legitimate or fraudulent?
      - Can I give the adaptive authentication engine feedback on a specific user's auth event?
      instructions:
      - text: Mark auth event {event_id} for user {username} in pool {user_pool_id} as {feedback}.
        slots:
          event_id: requestBody.EventId
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          feedback: requestBody.FeedbackValue
      - text: As an admin, report {username}'s sign-in event {event_id} in pool {user_pool_id} as {feedback}.
        slots:
          username: requestBody.Username
          event_id: requestBody.EventId
          user_pool_id: requestBody.UserPoolId
          feedback: requestBody.FeedbackValue
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateDeviceStatus'].post
  update:
    x-apievangelist-phrasing:
      intent: Change a user's device remembered status as an admin
      effect: write
      questions:
      - How does an admin mark a user's device as remembered or not remembered?
      - Can I stop remembering a user's device without forgetting it entirely?
      instructions:
      - text: Set device {device_key} for user {username} in pool {user_pool_id} to {status}.
        slots:
          device_key: requestBody.DeviceKey
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          status: requestBody.DeviceRememberedStatus
      - text: As an admin, mark {username}'s device {device_key} in pool {user_pool_id} as not remembered.
        slots:
          username: requestBody.Username
          device_key: requestBody.DeviceKey
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateUserAttributes'].post
  update:
    x-apievangelist-phrasing:
      intent: Update a user's attributes as an admin
      effect: write
      questions:
      - How does an admin change a user's email, name or custom attributes?
      - Can I mark a user's email as verified when updating their profile from the backend?
      instructions:
      - text: Update attributes for user {username} in pool {user_pool_id} to {attributes}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          attributes: requestBody.UserAttributes
      - text: As an admin, set {username}'s profile fields in pool {user_pool_id} to {attributes}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
          attributes: requestBody.UserAttributes
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUserGlobalSignOut'].post
  update:
    x-apievangelist-phrasing:
      intent: Sign a user out of all devices as an admin
      effect: destructive
      questions:
      - How can an admin sign a compromised user out everywhere by revoking their refresh tokens?
      - Can I force a specific user to log out on every device?
      instructions:
      - text: Sign user {username} out of all sessions in pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      - text: As an admin, revoke every refresh token for {username} in user pool {user_pool_id}.
        slots:
          username: requestBody.Username
          user_pool_id: requestBody.UserPoolId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken'].post
  update:
    x-apievangelist-phrasing:
      intent: Start setting up an authenticator app for MFA
      effect: write
      questions:
      - How do I get the secret code a user scans into an authenticator app for TOTP MFA?
      - Can I begin authenticator app enrollment during a sign-in session instead of with an access token?
      instructions:
      - text: Generate a TOTP secret to register an authenticator app for the user with access token {access_token}.
        slots:
          access_token: requestBody.AccessToken
      - text: Start authenticator app MFA setup in sign-in session {session}.
        slots:
          session: requestBody.Session
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ChangePassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Change the signed-in user's password
      effect: write
      questions:
      - How does a signed-in user change their own password?
      - Does a user need their old password to set a new one?
      instructions:
      - text: Change my password from {old_password} to {new_password} using access token {access_token}.
        slots:
          old_password: requestBody.PreviousPassword
          new_password: requestBody.ProposedPassword
          access_token: requestBody.AccessToken
      - text: Replace the current user's password {old_password} with {new_password} (token {access_token}).
        slots:
          old_password: requestBody.PreviousPassword
          new_password: requestBody.ProposedPassword
          access_token: requestBody.AccessToken
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmDevice'].post
  update:
    x-apievangelist-phrasing:
      intent: Confirm and start tracking a new device
      effect: write
      questions:
      - How does an app register a device so Cognito can remember it for the signed-in user?
      - Can I give a friendly name to a device when confirming it?
      instructions:
      - text: Confirm device {device_key} for the user with access token {access_token}.
        slots:
          device_key: requestBody.DeviceKey
          access_token: requestBody.AccessToken
      - text: Start tracking device {device_key} as {device_name} for the signed-in user ({access_token}).
        slots:
          device_key: requestBody.DeviceKey
          device_name: requestBody.DeviceName
          access_token: requestBody.AccessToken
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmForgotPassword'].post
  update:
    x-apievangelist-phrasing:
      intent: Set a new password with a reset code
      effect: write
      questions:
      - How does a user finish resetting a forgotten password with the code they received?
      - What do I submit along with the confirmation code to complete a password reset?
      instructions:
      - text: Complete the password reset for {username} with code {code} and new password {password} via client {client_id}.
        slots:
          username: requestBody.Username
          code: requestBody.ConfirmationCode
          password: requestBody.Password
          client_id: requestBody.ClientId
      - text: Use reset code {code} to set {username}'s new password to {password} on app client {client_id}.
        slots:
          code: requestBody.ConfirmationCode
          username: requestBody.Username
          password: requestBody.Password
          client_id: requestBody.ClientId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmSignUp'].post
  update:
    x-apievangelist-phrasing:
      intent: Confirm a self sign-up with a code
      effect: write
      questions:
      - How does a new user confirm their registration with the code emailed or texted to them?
      - Can confirming sign-up move an email alias from another account?
      instructions:
      - text: Confirm sign-up for {username} with code {code} on app client {client_id}.
        slots:
          username: requestBody.Username
          code: requestBody.ConfirmationCode
          client_id: requestBody.ClientId
      - text: Verify new registration {username} using confirmation code {code} through client {client_id}.
        slots:
          username: requestBody.Username
          code: requestBody.ConfirmationCode
          client_id: requestBody.ClientId
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.CreateGroup'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a user group
      effect: write
      questions:
      - How do I create a group like admins or editors in my user pool?
      - Can I attach an IAM role and a precedence to a new group?
      instructions:
      - text: Create group {group} in user pool {user_pool_id}.
        slots:
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
      - text: Add a new group {group} to pool {user_pool_id} with role {role_arn} and precedence {precedence}.
        slots:
          group: requestBody.GroupName
          user_pool_id: requestBody.UserPoolId
          role_arn: requestBody.RoleArn
          precedence: requestBody.Precedence
      method: generated
      generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.CreateIdentityProvider'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a third-party identity provider to a user pool
      effect: write
      questions:
      - How do I let users sign in to my user pool with SAML or an OIDC provider?
      - Can I map attributes from an external identity provider onto user pool attributes?
      instructions:
      - text: Add identity provider {provider_name} of type {provider_type} to pool {user_pool_id} with details {details}.
        slots:
          provider_name: requestBody.ProviderName
          provider_type: requestBody.ProviderType
          user_pool_id: requestBody.UserPoolId
          details: requestBody.ProviderDetails
      - text: Set up {provider_type} federation called {provider_name} in pool {user_pool_id} using {details} and attribute mapping {mapping}.
        slots:
          provider_type: requestBody.ProviderType
          provider_name: requestBody.ProviderName
          user_pool_id: requestBody.UserPoolId
          details: requestBody.ProviderDetails
          mapping: requestBody.AttributeMapping
      method: generated
      generated: '2026-10-01'


# --- truncated at 32 KB (89 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/amazon-cognito/refs/heads/main/overlays/amazon-cognito-amazon-cognito-identity-provider-api-phrasing-overlay.yaml